Privacy Policy
Last updated: August 2026
1. Data We Collect
We collect the following personal data:
- Account data: email address, name, and hashed password.
- Usage data: credit consumption, project metadata, and timestamps.
- Payment data: processed by Stripe; we do not store card numbers.
- Deck content: the text extracted from the PPTX and PDF files you submit. See section 3 for what we do and do not do with it.
- Analysis packs: the search vocabulary used to research your deck, including any pack you generate or edit. See section 5.
2. How We Use Your Data
- To provide the Service.
- To improve the Service, excluding the content of your decks, which is never used for this purpose. See section 3.
- To process payments and manage subscriptions.
- To send transactional emails (verification, password reset, billing).
- To enforce our Terms of Service.
3. Your Deck Content
Analysing a deck requires processing what is on it. This section states exactly what that involves and what it does not.
We commit that:
- We do not read your decks. No one at FactRefresh accesses your deck content except where you explicitly ask us to in order to resolve a support issue you have raised.
- We do not train any model on your decks, and we do not use them to improve the Service, tune our search vocabulary, or build datasets.
- We do not write your deck content to our application logs. Our processing logs record counts, timings and error types, not the text of your slides, and not the search queries derived from it.
- We do not sell your data or share it for advertising.
To be equally clear about what does happen:
- Deck text is stored in our database for as long as the project exists, because the review screen displays it. Deleting the project deletes it.
- Slide content is sent to Anthropic for analysis, and search queries built from the names on your slides are sent to our search provider. Both are listed in section 4.
- Our staff can technically access the database that holds this data, as with any hosted service. The commitment above is that we do not, not that it is impossible.
4. Third-Party Services
We use the following third-party services to operate FactRefresh:
- Anthropic API: slide content is sent to Anthropic's Claude models for AI analysis. Anthropic does not use API inputs for training. See Anthropic's privacy policy.
- Tavily / Brave Search: web search queries derived from your slide content. A query typically names a company and a product taken from your deck, so those names reach the search provider.
- Stripe: payment processing.
- Resend: transactional email delivery.
- AWS: infrastructure hosting.
5. Analysis Packs
An analysis pack is the vocabulary FactRefresh uses to research your deck: the kinds of development it looks for and the search phrasings it uses. You can choose one of our built-in packs, edit a copy, or generate one from a description you write of your field.
A pack is built from your description, never from your deck. Generation reads the text you type into the description box and nothing else, so a pack contains general vocabulary for a field rather than anything specific to your slides.
Packs you create are private to your account by default. If you tick "Allow this pack to be used to improve FactRefresh", you are giving us permission to view that pack and the description it was generated from, and to use them to improve our built-in packs. That permission covers the pack only. It does not extend to your decks, and ticking it changes nothing in section 3. You can withdraw it at any time in the pack's settings, and we will stop using it from that point.
6. File Retention
The file you upload is not retained. It is read into memory, the text is extracted, and the original file is not written to storage.
The extracted text is kept, because the review screen displays it, and that is what you come back to. It lives for as long as the project does. Deleting a project deletes its slides, its suggestions and its cited sources immediately, and deleting your account deletes all of them.
You can delete your account yourself, from the billing page. It is immediate and permanent. There is no grace period and no backup copy of your projects to restore from. Cancel your subscription first if you have one, or Stripe will keep billing a customer who no longer has an account.
7. Cookies
We use session cookies for authentication. We do not use third-party tracking cookies or analytics scripts.
8. Your Rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your data.
- Export your data in a portable format.
- Withdraw consent at any time.
- Lodge a complaint with a supervisory authority.
Deletion and export you can do yourself: deletion from the billing page, and export from any project's review screen. For the rest, contact us at the email address listed below.
9. Data Security
Traffic between your browser and FactRefresh is encrypted in transit (TLS). Files you upload are encrypted at rest with AES-256 by our storage provider — though, as section 6 says, we do not keep them. Passwords are hashed with bcrypt. API keys and secrets are held in environment variables, never in source code.
10. Changes
We may update this policy from time to time. Changes take effect upon posting. Continued use of the Service constitutes acceptance.
11. Contact
For privacy-related inquiries, contact us at [email protected].